{"id":"CVE-2026-59711","aliases":["GHSA-cr32-g25g-vxjj"],"url":"https://o3.security/vulnerability/CVE-2026-59711","summary":"showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLDocument","details":"showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.","published":"2026-07-06T21:00:38.491Z","modified":"2026-08-19T21:41:59.616958826Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"showdown","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59711.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59711"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/showdown-cross-site-scripting-via-unescaped-metadata-title-in-completehtmldocument"},{"type":"REPORT","url":"https://github.com/showdownjs/showdown/issues/1047"},{"type":"PACKAGE","url":"https://github.com/showdownjs/showdown"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T21:41:59.616958826Z"}}